Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
1271 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.8) | 0.20% | — | Nvidia Display Driver FOR WindowsAI | 28/1/2026 | 17/6/2026 | NVIDIA Display Driver for Windows contains a vulnerability where an attacker could trigger a use after free. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure. | |
| Aplazada | Alta (8.5) | 0.20% | — | Wondershare Driver Install ServiceAI | 27/1/2026 | 17/6/2026 | Wondershare Driver Install Service contains an unquoted service path vulnerability in the ElevationService executable that allows local attackers to potentially inject malicious code. Attackers can exploit the unquoted path to replace the service binary with a malicious executable, enabling privilege escalation to… | |
| Modificada | Alta (7.3) | 0.16% | 💥 PoC | Ludashi Driver | 15/1/2026 | 5/7/2026 | A local information disclosure vulnerability exists in the Ludashi driver before 5.1025 due to a lack of access control in the IOCTL handler. This driver exposes a device interface accessible to a normal user and handles attacker-controlled structures containing the lower 4GB of physical addresses. The handler maps… | |
| Analizada | Media (6.4) | 0.16% | — | Espressif USB Host HID Driver | 12/1/2026 | 17/6/2026 | Espressif ESP-IDF USB Host HID (Human Interface Device) Driver allows access to HID devices. Prior to 1.1.0, calls to hid_host_device_close() can free the same usb_transfer_t twice. The USB event callback and user code share the hid_iface_t state without locking, so both can tear down a READY interface simultaneously,… | |
| Analizada | Media (6.8) | 0.21% | — | Espressif USB Host HID Driver | 12/1/2026 | 17/6/2026 | Espressif ESP-IDF USB Host HID (Human Interface Device) Driver allows access to HID devices. Prior to 1.1.0, usb_class_request_get_descriptor() frees and reallocates hid_device->ctrl_xfer when an oversized descriptor is requested but continues to use the stale local pointer, leading to an immediate use-after-free when… | |
| Analizada | Media (6.8) | 0.24% | — | Espressif USB Host UVC Class Driver | 12/1/2026 | 17/6/2026 | Espressif ESP-IDF USB Host UVC Class Driver allows video streaming from USB cameras. Prior to 2.4.0, a vulnerability in the esp-usb UVC host implementation allows a malicious USB Video Class (UVC) device to trigger a stack buffer overflow during configuration-descriptor parsing. When UVC configuration-descriptor… | |
| Aplazada | Media (5.1) | 0.26% | — | Legrand Bticino Driver Manager F454AI | 24/12/2025 | 17/6/2026 | Legrand BTicino Driver Manager F454 1.0.51 contains multiple web vulnerabilities that allow attackers to perform administrative actions without proper request validation. Attackers can exploit cross-site request forgery to change passwords and inject stored cross-site scripting payloads through unvalidated GET… | |
| Analizada | Media (4) | 0.18% | 💥 PoC | ARM 5TH GEN GPU Architecture Kernel DriverARM Valhall GPU Kernel Driver | 1/12/2025 | 17/6/2026 | Use After Free vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform improper GPU processing operations to gain access to already freed memory.This issue affects Valhall GPU Kernel Driver: from r53p0 through r54p1;… | |
| Analizada | Media (5.1) | 0.17% | — | ARM 5TH GEN GPU Architecture Kernel DriverARM Valhall GPU Kernel Driver | 1/12/2025 | 17/6/2026 | Use After Free vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform improper GPU memory processing operations to gain access to already freed memory.This issue affects Valhall GPU Kernel Driver: from r53p0 through… | |
| Analizada | Media (5.1) | 0.13% | — | ARM 5TH GEN GPU Architecture Kernel DriverARM Valhall GPU Kernel Driver | 1/12/2025 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform improper GPU processing operations to expose sensitive data.This issue affects Valhall GPU Kernel… | |
| Aplazada | Alta (7.5) | 0.24% | — | Teradata DriverAIGoogle LookerAI | 25/11/2025 | 17/6/2026 | A Looker user with a Developer role could cause Looker to execute a malicious command, due to insecure processing of Teradata driver parameters. Looker-hosted and Self-hosted were found to be vulnerable. This issue has already been mitigated for Looker-hosted instances. No user action is required for these. | |
| Aplazada | Alta (8.6) | 0.30% | — | Progress Datadirect Connect FOR Jdbc FOR Amazon RedshiftAIProgress Datadirect Connect FOR Jdbc FOR Apache CassandraAIProgress Datadirect Connect FOR Jdbc FOR HiveAIProgress Datadirect Connect FOR Jdbc FOR Apache ImpalaAI+28 | 19/11/2025 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Progress DataDirect Connect for JDBC drivers, Progress DataDirect Open Access JDBC driver and Hybrid Data Pipeline allows Remote Code Inclusion. The SpyAttribute connection option implemented by the DataDirect Connect for JDBC drivers,… | |
| Aplazada | Alta (8.6) | 0.30% | — | Progress Datadirect Connect FOR Jdbc FOR Amazon RedshiftAIProgress Datadirect Connect FOR Jdbc FOR Apache CassandraAIProgress Datadirect Connect FOR Jdbc FOR HiveAIProgress Datadirect Connect FOR Jdbc FOR Apache ImpalaAI+28 | 19/11/2025 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Progress DataDirect Connect for JDBC drivers, Progress DataDirect Open Access JDBC driver and Hybrid Data Pipeline allows Remote Code Inclusion. The SpyAttribute connection option implemented by the DataDirect Connect for JDBC drivers,… | |
| Modificada | Media (6.9) | 0.20% | — | Mongodb C DriverMongodb PHP Driver | 18/11/2025 | 7/10/2026 | A mongoc_bulk_operation_t may read invalid memory if large options are passed. | |
| Aplazada | Media (5.4) | 0.11% | — | PRI DriverAI | 11/11/2025 | 17/6/2026 | Unquoted search path for some PRI Driver software before version 03.03.1002 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via… | |
| Aplazada | Media (5.1) | 0.12% | — | Intel Ethernet Adapter Complete Driver PackAI | 11/11/2025 | 17/6/2026 | Time-of-check time-of-use race condition for some Intel Ethernet Adapter Complete Driver Pack software before version 1.5.1.0 within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service.… | |
| Aplazada | Media (5.4) | 0.13% | — | Intel Driver AND Support AssistantAI | 11/11/2025 | 17/6/2026 | Uncontrolled search path for some Intel Driver and Support Assistant before version 25.2 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable local code execution. This result may potentially… | |
| Aplazada | Media (5.1) | 0.12% | — | Intel NPU DriversAI | 11/11/2025 | 17/6/2026 | Improper control of dynamically-managed code resources for some Intel(R) NPU Drivers within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local… | |
| Aplazada | Media (6.8) | 0.13% | — | Intel NPU DriversAI | 11/11/2025 | 17/6/2026 | Protection mechanism failure for some Intel(R) NPU Drivers within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when attack… | |
| Aplazada | Baja (2) | 0.12% | — | Intel Graphics DriversAIIntel LTS KernelAI | 11/11/2025 | 17/6/2026 | Improper input validation in some firmware for some Intel(R) Graphics Drivers and Intel LTS kernels within Ring 1: Device Drivers may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially… | |
| Aplazada | Baja (2) | 0.13% | — | Intel NPU DriversAI | 11/11/2025 | 17/6/2026 | Sensitive information uncleared in resource before release for reuse for some Intel(R) NPU Drivers for Windows before version 32.0.100.4023 within Ring 3: User Applications may allow an information disclosure. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable… | |
| Aplazada | Alta (8.6) | 0.73% | — | Amazon Aurora PostgresqlAIAmazon Jdbc WrapperAIAmazon GO WrapperAIAmazon Nodejs WrapperAI+2 | 10/11/2025 | 17/6/2026 | An issue in AWS Wrappers for Amazon Aurora PostgreSQL may allow for privilege escalation to rds_superuser role. A low privilege authenticated user can create a crafted function that could be executed with permissions of other Amazon Relational Database Service (RDS) users. We recommend customers upgrade to the… | |
| Aplazada | Media (5.5) | 0.28% | 💥 PoC | Gamedriverx64AI | 28/10/2025 | 17/6/2026 | The GameDriverX64.sys kernel-mode anti-cheat driver (v7.23.4.7 and earlier) contains an access control vulnerability in one of its IOCTL handlers. A user-mode process can open a handle to the driver device and send specially crafted IOCTL requests. These requests are executed in kernel-mode context without proper… | |
| Aplazada | Media (6.2) | 0.13% | — | Realtek Ndis Usermode IO DriverAI | 24/10/2025 | 5/7/2026 | An issue was discovered in the NDIS Usermode IO driver (RtkIOAC60.sys, version 6.0.5600.16348) allowing local authenticated attackers to send a crafted IOCTL request to the driver to cause a denial of service. | |
| Aplazada | Alta (8.8) | 0.17% | — | Mongodb BI Connector Odbc DriverAI | 23/10/2025 | 17/6/2026 | Incorrect Default Permissions vulnerability in MongoDB BI Connector ODBC driver allows Privilege Escalation.This issue affects BI Connector ODBC driver: from 1.0.0 through 1.4.6. |